Our call: Is ipscan-3.9.3-setup.exe safe?Suspicious
This unsigned installer exhibits suspicious process injection and credential-dumping behaviors, alongside specific detections for file-infecting malware, warranting caution despite low overall engine consensus.
- 1 high-confidence signature or behavior rule matched this file.Derived · Signature and behavior rules
- 2 of 74 antivirus engines flagged the file, including CrowdStrike and Malwarebytes.Observed · Antivirus analysis
- The hash has a long, established submission history across 2,483 sources.Derived · Submission history
91d77c63169249e8fc…13fb49f9f5Recommended next actions
Before installing
Do not install it until the source and publisher can be verified independently.
If you already installed it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Download a fresh installer from the developer's official site or an official app store.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete2 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
Complete2 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
ipscan-3.9.3-setup.exe
91d77c63169249e8fcdd2d912963d4d5cd143d87b65352fc62ba8113fb49f9f5
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\Desktop\software.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\Explorer.EXE
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
nsaCC0B.tmp
C:\Users\<USER>\AppData\Local\Temp\nsaCC0B.tmp
04Isolated runtime analysis - Written fileObserved
UserInfo.dll
C:\Users\<USER>\AppData\Local\Temp\nsfCC2B.tmp\UserInfo.dll
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
2 of 74 antivirus engines flagged the file, including CrowdStrike and Malwarebytes.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has a long, established submission history across 2,483 sources.
ProvenanceDerivedSourceSubmission historyObserved at - 04
Scanned file: ipscan-3.9.3-setup.exe — 91d77c63169249e8fcdd2d912963d4d5cd143d87b65352fc62ba8113fb49f9f5
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\software.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\Explorer.EXE
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: nsaCC0B.tmp — C:\Users\<USER>\AppData\Local\Temp\nsaCC0B.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: UserInfo.dll — C:\Users\<USER>\AppData\Local\Temp\nsfCC2B.tmp\UserInfo.dll
ProvenanceObservedSourceIsolated runtime analysisObserved at
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The file is unsigned and lacks a verified publisher, which is unusual for legitimate software. Our analysis identified high-severity process injection and credential-dumping behaviors, which are commonly associated with malicious activity. While most engines did not flag the file, the presence of these behaviors and specific detections for file-infecting malware makes this sample suspicious.
The sample is an unsigned executable that performs actions typically reserved for malicious software, such as process injection and accessing the LSASS process. Although the majority of the 74 engines in our network did not flag the file, the specific detections for the Neshta virus family and the observed offensive MITRE techniques cannot be ignored. The discrepancy between the sandbox reports and the heuristic detections suggests that the file may behave differently depending on the environment. Given the lack of a valid digital signature and the presence of credential-dumping indicators, we cannot classify this as safe.
What We Detected
Our analysis identified an unsigned executable that triggers high-severity heuristics related to process injection (T1055) and credential dumping (LSASS access). While the majority of the 74 engines in our network did not flag the file, specific detections from Malwarebytes and CrowdStrike point toward grayware and file-infecting behavior.
Threat Behavior
The file demonstrated offensive techniques including process injection, token manipulation, and data destruction (T1485). The attempt to access LSASS memory is particularly concerning, as this is a common technique used by credential-dumping tools to extract sensitive information from the Windows credential store.
What To Do Now
We recommend treating this file as suspicious. Do not execute it on production systems or machines containing sensitive data. If you must use the software, ensure it is obtained directly from the official vendor's website and verify the digital signature, which is absent in this sample. Keep your endpoint protection enabled and updated.
Where this verdict could be wrong2 caveats
- Multiple community comments from automated sandbox reports label the file as 'CLEAN' with low scores.
- The majority of the 74 engines (72/74) did not flag the file as malicious, suggesting the detections might be heuristic-based or specific to certain environments.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Low engine detection rate (2/74)
- Commonly submitted file (2483 unique sources)
- Unsigned executable
- Process injection (T1055)
- Credential dumping behavior (LSASS access)
- File-infector detection (Neshta)
- Offensive MITRE techniques observed
Do not run this file. If you require this software, download it only from the official developer's website and verify that the file is digitally signed by the legitimate publisher.
Behavior
Plain-English impact first, then the observed runtime evidence.
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Changed an auto-start location that can make code run after sign-in or restart.
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Moderate concern: Runs hidden system commands (script or shell).
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Scans through your files and folders.
Moderate concern: Decoded or unpacked concealed content while running.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Users\<USER>\AppData\Local\Temp\nsaCC0B.tmp
- C:\Users\<USER>\AppData\Local\Temp\nsfCC2B.tmp\UserInfo.dll
- C:\Users\<USER>\AppData\Local\Temp\nsfCC2B.tmp\System.dll
- C:\Users\<USER>\AppData\Local\Temp\nsfCC2B.tmp\modern-header.bmp
- C:\Users\<USER>\AppData\Local\Temp\nsfCC2B.tmp\modern-wizard.bmp
- C:\Users\<USER>\AppData\Local\Temp\nsfCC2B.tmp\modern-header.bmp
- C:\Users\<USER>\AppData\Local\Temp\nsfCC2B.tmp\modern-wizard.bmp
- C:\Users\<USER>\AppData\Local\Temp\nsfCC2B.tmp\nsDialogs.dll
- C:\Users\<USER>\AppData\Local\Temp\nsfCC2B.tmp\System.dll
- C:\Users\<USER>\AppData\Local\Temp\nsfCC2B.tmp\UserInfo.dll
- cversions.3.m
- Local\MSCTF.Asm.MutexDefault1
- DefaultTabtip-MainUI
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- d5ba4596f19f490aacc3…10d2deNever scannednever seen before
- 361ebbef6e0d77624560…a4ed48Never scannednever seen before
- b62d2733ab99556b108a…46c56fNever scannednever seen before
- 39dbe64591ef5d0aa48b…2dea53Never scannednever seen before
- 41dd8451c6b25a7a924a…adb97aNever scannednever seen before
- 24dd4de212b4b43c2e3d…4aedb8Never scannednever seen before
- 4451084c3993c3a1bd3e…f22103Never scannednever seen before
- cf7dc6f5abe58e31b419…703536Never scannednever seen before
- 52785bb917c6e38fb69e…64fb7cNever scannednever seen before
- 6da0747334b0fea7592f…e98eb5Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Detection sources at a glance
Category: generic-trojan
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\Explorer.EXESandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exe
2 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- ipscan-3.9.3-setup.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 21.1 MB
- Last analyzed
- Jul 28, 2026, 5:56 PM UTC
91d77c63169249e8fcdd2d912963d4d5cd143d87b65352fc62ba8113fb49f9f5Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
Don't install it unless you're certain it came from a source you trust.
Check where you got it — an unexpected attachment or a random download link is a red flag.
If its origin cannot be confirmed, delete this file and use a fresh copy from a trusted source. Download a fresh installer from the developer's official site or an official app store.
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.